Client Success Story

Storefront: SOC 2 Type I, Passed

How fractional CISO leadership took a fintech reporting platform from no formal compliance program to an independently attested SOC 2 Type I report.

Storefront

$6.1B

Assets under data management

7,400

Accounts tracked

Type I

SOC 2 examination scope

Jun 2026

Report issued

Platform data as of December 31, 2025.

Client Overview

Storefront is a fintech company building performance-reporting technology for financial advisors, specializing in Private Placement Life Insurance (PPLI) and Private Placement Variable Annuity (PPVA) reporting.

The platform helps top-tier PPLI/PPVA producers deliver accurate, client-specific reporting: pre- and post-carrier-fee account performance, multi-policy and multi-carrier portfolio views, insurance-dedicated fund (IDF) share-class performance, separately managed account (SMA) tracking, and personal rate-of-return calculations for registered investment VITs.

Because Storefront ingests, processes, and reports on sensitive high-net-worth client financial and insurance data through cloud infrastructure and ETL pipelines, third-party security assurance became a business necessity for winning and retaining enterprise advisory-firm clients.

Platform Footprint

$6.1 billion in assets

Across 7,400 accounts as of year-end 2025.

Multi-product coverage

PPLI/PPVA contracts, VUL and IUL accounts within COLI plans, and carrier data services.

Carrier relationships

Prudential, John Hancock, Zurich, Pacific Life, and New York Life.

Engagement Scope

Rivia served as fractional CISO, leading Storefront through a SOC 2 Type I examination end to end.

Why Type I first

A Type I examination evaluates whether security controls are appropriately designed and in place at a specific point in time, rather than testing operating effectiveness over an extended monitoring period.

The growth-stage fit

Type I is the common first step for technology and fintech companies with limited prior compliance infrastructure. It validates control design faster and at lower cost, typically two to three months against the six-to-twelve-month window Type II testing requires.

The SOC 2 readiness lifecycle

1

Define scope

Set the audit boundary and applicable Trust Services Criteria.

2

Map & remediate

Close gaps across technical and administrative controls.

3

Document

Produce the policy set and evidence the auditor will sample.

4

Coordinate

Work directly with the third-party auditor through to issuance.

Remediation & Technical Setup

A central pillar of the engagement was bringing Storefront's AWS environment into alignment with the SOC 2 Security (Common Criteria) requirements.

Cloud environment

Auditors scrutinize cloud architecture, IAM configuration, encryption, logging, and monitoring for infrastructure-hosted fintech platforms. Remediation addressed identity and access management, network segmentation, encryption at rest and in transit, vulnerability and patch management, backup and disaster recovery, and continuous monitoring and alerting, each backed by documented policy and system-generated evidence.

Storefront's stack, spanning AWS console management, Python-based ETL processes, and separate production, staging, and development databases, meant the work extended to tightening access controls and change-management discipline across the engineering and data pipeline tooling.

Policy & process

Beyond infrastructure, readiness required building and upgrading the information security policy set, aligning internal procedures to those policies, and establishing evidence-collection mechanisms the auditor could sample against.

Acceptable use

Incident response

Vendor risk management

Data classification

Access control

Standard Common Criteria expectations were addressed alongside them: enforcing multi-factor authentication, formalizing onboarding and offboarding access reviews, documenting a risk assessment process, and ensuring vendor and sub-processor due diligence records exist.

Audit Leadership & Coordination

Someone has to run point on a SOC 2 effort: defining scope, coordinating engineering, operations, and leadership, and managing the audit timeline end to end. The fractional CISO role served as that project lead.

That meant preparing for and attending audit meetings with the third-party auditor, acting as primary liaison to clarify control descriptions and respond to auditor inquiries, and advocating for realistic compliance expectations on the client's behalf.

Internally it meant pulling technical and administrative evidence from teams that do not naturally speak the auditor's language, namely client operations staff ingesting carrier data via email, Excel, PDF, and FTP, and backend developers running the AWS-hosted Python application and its databases, then translating that operational reality into auditor-ready control narratives.

The Outcome

SOC 2 Type I passed, June 2026, via Thoropass

Storefront now holds a formal, independent attestation that its security controls were suitably designed as of the report date, a market-facing credential that reassures PPLI/PPVA advisory firms, insurance carriers, and ultra-high-net-worth family clients that platform security meets an independently verified standard.

The Type I report is also the standard precursor to a SOC 2 Type II examination, which tests the operating effectiveness of these same controls over a monitoring period of six months or more.

"The vCISO advisory service has been transformative for our organization. Having strategic security leadership without the cost of a full-time executive has allowed us to mature our security program while staying within budget."

Matthew White

Chief Executive Officer, Storefront

Key Takeaways

Engagement Dimension Detail
Client Storefront, a fintech PPLI/PPVA performance reporting platform
Assets under data management $6.1 billion across 7,400 accounts (as of 12/31/2025)
Audit type SOC 2 Type I (point-in-time control design assessment)
Audit platform Thoropass
Outcome Passed, June 2026
Fractional CISO role AWS and systems remediation, policy development, audit meeting leadership, cross-team coordination

Facing your first SOC 2?

Rivia's fractional CISO engagements take growth-stage companies from no formal compliance program to an issued report, covering scoping, remediation, documentation, and auditor coordination.